CVE-2024-55636

Drupal core - Less critical - Gadget chain - SA-CORE-2024-006

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.


We have discovered 123,597 live websites that are affected by CVE-2024-55636.

Test my site




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains123,597 live websites (49.20% of Drupal install base)
Vulnerable Versions
  • from 8 before 10.2.11
  • from 10.3 before 10.3.9
  • from 11 before 11.0.8
Vulnerable Versions Count269 versions ( 88.20% of all versions)


Common Weakness Enumeration

CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes



Details

  • Published - Dec 9, 2024
  • Updated - Dec 16, 2024

Credits

  • Drew Webber (finder)
  • Drew Webber (remediation developer)
  • Lee Rowlands (remediation developer)
  • Juraj Nemec (coordinator)
  • Benji Fisher (coordinator)
  • xjm (coordinator)

CVE-2024-55636 usage by Country

United States52,623 websites



Germany13,436 websites
France9,552 websites
Belgium5,382 websites
Netherlands4,563 websites
Russia3,468 websites
GB3,414 websites
Switzerland2,614 websites
Spain2,415 websites
Canada2,087 websites

CVE-2024-55636 usage by TLD

.com33,123 websites
.org12,024 websites
.de8,230 websites
.edu7,583 websites
.be5,671 websites
.fr5,182 websites
.nl3,656 websites
.ru2,951 websites
.net2,346 websites
.ch2,331 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-55636

Top websites that are affected by CVE-2024-55636. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk United States***
***.gov United States***
****.fr France***
***.gov United States***
***.gov United States*,***
***.org France*,***
**************************.nl Netherlands*,***
***.gov United States*,***
*******.gov United States*,***
***.gov United States*,***
See full domain list

FAQ

CVE-2024-55636 is Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal
A total of 123,597 websites have been identified as vulnerable to CVE-2024-55636, discovered through global website indexing conducted by WebTechSurvey.
Drupal is susceptible to CVE-2024-55636 vulnerability.
Drupal versions before 11.0.8 are vulnerable to CVE-2024-55636.
Version 11.0.8 of Drupal addresses the CVE-2024-55636 security vulnerability.